如何通过组策略(GPO)运行PowerShell脚本修改Windows管理员密码?
问题描述
在Samba 4域环境中,使用安装RSAT的Windows 10工作站管理域。编写的PowerShell脚本在本地运行可成功修改本地Administrator用户密码,但配置为域计算机启动脚本的GPO后无法生效。
原脚本:
# Save current execution policy $currentExecutionPolicy = Get-ExecutionPolicy # Temporarily disable execution policy (make it possible to run scripts) Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass # Set the local Administrator user path $computer = "." $adminUser = [ADSI]"WinNT://$computer/Administrator,user" # Set a new password that will be assigned to the local Administrator user $newPassword = "mypassword" # Attempting to change the local Administrator user password try { $adminUser.SetPassword($newPassword) $adminUser.SetInfo() Write-Host "Local Administrator user password has been successfully changed!" Start-Sleep -Seconds 5 } catch { Write-Host "An error occurred while changing the Administrator user password: $_" Start-Sleep -Seconds 5 } # Restore the original execution policy Set-ExecutionPolicy -Scope Process -ExecutionPolicy $currentExecutionPolicy
可能原因及解决方案
1. 启动脚本无交互环境,日志缺失
计算机启动脚本以本地系统账户后台运行,Write-Host输出无法直接查看,无法定位失败原因。需修改脚本添加日志记录:
修改后的带日志脚本
$logPath = "C:\Windows\Temp\LocalAdminPasswordChange.log" $currentDate = Get-Date -Format "yyyy-MM-dd HH:mm:ss" # 写入日志起始记录 Add-Content -Path $logPath -Value "[$currentDate] 开始执行本地管理员密码修改脚本..." # 处理执行策略 try { $currentExecutionPolicy = Get-ExecutionPolicy -ErrorAction Stop Add-Content -Path $logPath -Value "[$currentDate] 当前执行策略: $currentExecutionPolicy" Set-ExecutionPolicy -Scope Process -ExecutionPolicy Bypass -Force -ErrorAction Stop Add-Content -Path $logPath -Value "[$currentDate] 临时将执行策略设置为Bypass" } catch { Add-Content -Path $logPath -Value "[$currentDate] 设置执行策略失败: $_" exit 1 } # 密码修改逻辑 $computer = "." $adminUser = [ADSI]"WinNT://$computer/Administrator,user" $newPassword = "mypassword" try { $adminUser.SetPassword($newPassword) $adminUser.SetInfo() Add-Content -Path $logPath -Value "[$currentDate] 本地管理员密码修改成功!" } catch { Add-Content -Path $logPath -Value "[$currentDate] 密码修改失败: $_" } finally { # 恢复原执行策略 try { Set-ExecutionPolicy -Scope Process -ExecutionPolicy $currentExecutionPolicy -Force -ErrorAction Stop Add-Content -Path $logPath -Value "[$currentDate] 执行策略已恢复为 $currentExecutionPolicy" } catch { Add-Content -Path $logPath -Value "[$currentDate] 恢复执行策略失败: $_" } }
2. 本地安全策略限制
若本地密码策略要求复杂度、长度等规则,而设置的mypassword不符合,会导致修改失败。检查目标计算机本地安全策略:
- 运行
secpol.msc - 导航到账户策略 > 密码策略
- 确保密码符合
密码必须符合复杂性要求、密码长度最小值等规则
3. Samba4 GPO脚本执行配置问题
Samba4对GPO脚本的处理存在兼容性细节,需确认以下配置:
- 在GPO的计算机配置 > 脚本(启动/关机)中,确认勾选运行Windows PowerShell脚本,且脚本路径指向域控制器
NETLOGON共享(如\\domain.com\NETLOGON),域计算机有该共享的读取权限 - 检查GPO的计算机配置 > 管理模板 > 系统 > 脚本,确保
运行启动脚本未被禁用
4. 域级执行策略限制
如果域GPO设置了计算机级执行策略,会覆盖脚本中的Process级设置。检查域GPO的计算机配置 > 管理模板 > Windows组件 > Windows PowerShell,将Turn on Script Execution设置为允许本地脚本和远程签名脚本
排查步骤
- 查看目标计算机上的日志文件
C:\Windows\Temp\LocalAdminPasswordChange.log,定位具体错误 - 用本地系统账户手动运行脚本:
- 使用Sysinternals的
psexec.exe,执行命令:psexec -s powershell.exe -File "\\domain.com\NETLOGON\你的脚本名.ps1"
- 使用Sysinternals的
- 在目标计算机运行
gpresult /r,确认该GPO已成功应用 - 检查域控制器事件日志,查看GPO应用是否存在错误
内容的提问来源于stack exchange,提问作者campos
相关产品推荐
相关产品推荐

